syncfusion-javascript-common
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PERSISTENCE]: The skill provides instructions for modifying shell profiles (such as
~/.bash_profileon macOS/Linux) to store license keys as environment variables. This technique ensures the environment variable persists across different shell sessions and system restarts. - [INDIRECT_PROMPT_INJECTION]: The skill documents UI components like Grids and ListViews that interpolate data from a
dataSourceinto HTML templates. - Ingestion points:
dataSourceproperties in various UI controls as seen inSKILL.mdandreferences/advanced-features.md. - Boundary markers: The examples provided do not show explicit delimiters or boundary markers to prevent the execution of instructions embedded within the data interpolated into templates.
- Capability inventory: Capabilities include browser state persistence via
localStorage, DOM manipulation, and instructions for shell command execution for licensing and configuration. - Sanitization: The skill references security guidelines and HTML sanitization in its documentation, but the provided code examples do not demonstrate active sanitization of the interpolated data within the skill's own snippets.
- [COMMAND_EXECUTION]: The documentation includes shell commands for project setup and license activation, such as
npx syncfusion-license activate,setx,export, and platform-specific commands likecordova run. - [EXTERNAL_DOWNLOADS]: The skill references downloads for official packages and themes from the npm registry, GitHub repositories (
github.com/SyncfusionExamples), and the vendor's CDN (cdn.syncfusion.com). These are standard resources provided by the vendor for library integration and are documented neutrally.
Audit Metadata